---
id: CVE-2026-57583
title: >-
  OpenZeppelin Contracts Wizard is a web application to interactively build a
  contract out of components from OpenZeppelin Contracts
summary: >-
  OpenZeppelin Contracts Wizard is a web application to interactively build a
  contract out of components from OpenZeppelin Contracts. Prior to
  @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1,
  @openzeppelin/wizard-stellar 0.6…
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-94
  - CWE-116
vendor: OpenZeppelin
product: contracts-wizard
affected:
  - contracts-wizard < 0.10.11
  - wizard < 0.10.11
  - wizard-cairo < 3.0.1
  - wizard-stellar < 0.6.2
  - wizard-stylus < 0.3.1
published: '2026-09-14'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T19:17:37.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-57583'
references:
  - url: >-
      https://github.com/OpenZeppelin/contracts-wizard/commit/6b18ecbd727a22d9f8c592e5d56caa2e977fb225
    label: security-advisories@github.com
  - url: 'https://github.com/OpenZeppelin/contracts-wizard/pull/818'
    label: security-advisories@github.com
  - url: >-
      https://github.com/OpenZeppelin/contracts-wizard/releases/tag/@openzeppelin/wizard-cairo@3.0.1
    label: security-advisories@github.com
  - url: >-
      https://github.com/OpenZeppelin/contracts-wizard/releases/tag/@openzeppelin/wizard-stellar@0.6.2
    label: security-advisories@github.com
  - url: >-
      https://github.com/OpenZeppelin/contracts-wizard/releases/tag/@openzeppelin/wizard-stylus@0.3.1
    label: security-advisories@github.com
  - url: >-
      https://github.com/OpenZeppelin/contracts-wizard/releases/tag/@openzeppelin/wizard@0.10.11
    label: security-advisories@github.com
  - url: >-
      https://github.com/OpenZeppelin/contracts-wizard/security/advisories/GHSA-9wxg-vf3r-56hc
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T19:06:44.881137Z'
ingestedAt: '2026-09-14T19:13:23.459Z'
epss: 0.00187
epssPercentile: 0.07399
---

## Overview

OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Prior to @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar 0.6.2, and @openzeppelin/wizard-stylus 0.3.1, the setInfo code path prints info.securityContact and info.license verbatim into single-line comments in generated Solidity, Cairo, Stellar/Soroban, and Stylus source. A line terminator ends the comment and causes following input to be emitted as source declarations. Exploitation requires an integration to populate these fields from untrusted input and a user to consume the generated source; normal self-service web, AI assistant, CLI, and self-hosted API use does not cross that trust boundary, shared links cannot set the fields, and no code executes on a Wizard service. This issue affects generated-source integrity only and is fixed in versions 0.10.11, 3.0.1, 0.6.2, and 0.3.1 of the respective packages.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
